Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: GAO Urges EPA to Improve Water Sector Cybersecurity
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

GAO Urges EPA to Improve Water Sector Cybersecurity

Highlights

  • GAO urges EPA to strengthen water sector cybersecurity.

  • Water sector struggles with cyber hygiene and resource constraints.

  • EPA plans comprehensive risk assessment and peer reviews by 2025.

Ethan Moreno
Last updated: 2 August, 2024 - 12:26 am 12:26 am
Ethan Moreno 10 months ago
Share
SHARE

A recent report from the Government Accountability Office (GAO) highlights the pressing need for the Environmental Protection Agency (EPA) to enhance its cybersecurity support for the water sector. Amid increasing state-backed cyber threats, the GAO underscores the urgency for the EPA to formulate a national strategy to address the various cyber risks facing the sector. Officials have identified a lack of foundational cybersecurity practices and limited resources as significant obstacles. Historically, incidents involving hackers from Iran, China, and Russia have exposed vulnerabilities within U.S. water systems, emphasizing the need for stronger cyber defenses.

Contents
Challenges in Cybersecurity CultureRisk Assessments and Strategic Planning

Challenges in Cybersecurity Culture

The GAO report indicates that the water sector struggles to cultivate a comprehensive cybersecurity culture. This deficiency has led to inadequate cyber hygiene, compounded by resource constraints as physical infrastructure maintenance costs rise. Despite the Biden administration’s prioritization of water sector cybersecurity, the industry has resisted regulatory mandates aimed at improving cyber defenses.

Risk Assessments and Strategic Planning

The report reveals that the EPA has yet to conduct a sector-wide risk assessment or implement a risk-informed strategy, which are essential for effective risk mitigation. Without these, the agency lacks a “basic underpinning for managing federal programs,” according to the GAO. An inclusive risk assessment could help identify the highest risks and prioritize actions accordingly, providing a clearer direction for cybersecurity efforts.

EPA officials claim that while they have assessed threats and vulnerabilities, these efforts have not been consolidated into a comprehensive strategy. The GAO also noted the absence of defined cybersecurity goals, objectives, and performance metrics within the EPA’s plans. For instance, although the EPA aims for 100% of systems using certain technologies to have cybersecurity programs, it has not clearly identified or prioritized steps to achieve this target.

Furthermore, coordination issues have emerged as a significant hurdle. The Cybersecurity and Infrastructure Security Agency (CISA) has not fully integrated its cybersecurity expertise with the EPA’s water sector knowledge. This lack of coordination has led to inefficiencies and gaps in addressing cybersecurity threats.

The EPA also faces challenges with its tools for vulnerability assessments, which have not undergone external peer reviews. This lack of external validation raises questions about the credibility of these tools and their effectiveness in guiding cybersecurity measures.

EPA officials have agreed with the GAO’s recommendations to conduct a thorough risk assessment, develop a national strategy, and review the legal authorities needed to carry out risk mitigation responsibilities. The agency plans to complete the risk assessment by January 2025 and initiate a peer review of its risk tool in November.

The EPA has historically struggled with voluntary approaches to cybersecurity, facing resistance from the water sector in providing baseline information. The sector has pushed back against perceived federal overreach, complicating efforts to implement mandatory cybersecurity audits. Notably, in October 2023, the EPA withdrew a memo requiring cybersecurity audits following resistance from state authorities.

Additionally, previous reports have criticized the EPA for insufficient cybersecurity measures, attributing lapses to inadequate funding and lack of a cohesive strategy. The Cyberspace Solarium Commission recommended a significant increase in cybersecurity spending, but the EPA’s budget allocations have fallen short. This historical context underscores the ongoing challenges the agency faces in securing the water sector.

The EPA’s current cybersecurity initiatives need substantial improvements to effectively protect the water sector against sophisticated cyber threats. Implementing the GAO’s recommendations could enhance the agency’s ability to manage risks and safeguard critical infrastructure. A comprehensive national strategy, supported by adequate funding and resources, is crucial for addressing the cybersecurity vulnerabilities in the water sector.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Global Operation Disrupts 10 Million Device Malware Network

Russian Cyber Group Targets Western Firms Supporting Ukraine

Global Operation Strikes Lumma Stealer’s Core Infrastructure

US Telecom Faces Ongoing Battle with Salt Typhoon Hackers

Massachusetts Student Admits Guilt in Massive School Data Breach

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article BioWare Confirms Dragon Age: The Veilguard Launch Date
Next Article Dead Cells Final Update Launches on August 19

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Google Fast-Tracks AI Innovations in Latest Conference
Gaming
FCC Boosts Anti-Robocall Tactics Amid Growing Concerns
Technology
Hyundai Tests AI EV Charging Robot at Incheon Airport
Electric Vehicle
Embracer Reshapes Its Gaming Empire with Strategic Moves
Gaming
Anthropic Expands AI Capabilities with Claude 4 Series Launch
AI
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?